Tracking for Divi Security & Risk Analysis
wordpress.org/plugins/tracking-for-diviTrack successful Divi contact form submissions with dataLayer events, Google Analytics, and Google Ads conversions.
Is Tracking for Divi Safe to Use in 2026?
Generally Safe
Score 100/100Tracking for Divi has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the static analysis and vulnerability history provided, the 'tracking-for-divi' plugin v1.1.1 appears to have a strong security posture. The absence of any identified vulnerabilities in its history and the lack of critical signals in the code analysis, such as dangerous functions, raw SQL queries, or unsanitized taint flows, are highly positive indicators. The plugin also demonstrates good practices by using prepared statements for all SQL queries and a high percentage of properly escaped outputs, minimizing the risk of common web vulnerabilities.
However, a few areas warrant attention. The complete absence of nonce checks and capability checks on all entry points, coupled with the lack of any authentication checks on AJAX handlers and permission callbacks for REST API routes (though the count is zero, the absence of checks is notable), presents a potential blind spot. While the attack surface is currently zero, if any new entry points were introduced without proper checks, they could be immediately exploitable. The plugin's reliance on 100% prepared statements and 93% escaped output is commendable, but it's crucial to maintain this rigor as the plugin evolves. The overall security is good, but the lack of explicit security checks on potential future entry points is a minor concern.
In conclusion, 'tracking-for-divi' v1.1.1 exhibits excellent security hygiene with no known vulnerabilities and robust coding practices for its current features. The main weakness lies in the absence of inherent security checks (nonces, capabilities) on its (currently non-existent) entry points. This suggests the plugin is developed with security in mind, but future development should prioritize incorporating these checks if new functionalities are added that expose entry points.
Key Concerns
- No nonce checks on entry points
- No capability checks on entry points
Tracking for Divi Security Vulnerabilities
Tracking for Divi Code Analysis
Output Escaping
Tracking for Divi Attack Surface
WordPress Hooks 7
Maintenance & Trust
Tracking for Divi Maintenance & Trust
Maintenance Signals
Community Trust
Tracking for Divi Alternatives
Datalayer for WooCommerce FREE
datalayer-for-ecommerce-free
The Data Layer is an object that makes available in real time the information that is executed by users while browsing the WooCommerce Store.
Datalayer For Elementor
datalayer-for-elementor
Integration between the Elementor Forms and Datalayer
DataLayer for GTM and Matomo
datalayer
Add contextual information to dataLayer for GTM and MTM
Tracking Code for Google Tag Manager
tracking-code-for-google-tag-manager
Simple, lightweight solution for inserting your Google Tag Manager Universal tracking code.
TagSyncer – Free Google Tag Manager Plugin for WordPress
tag-syncer
Easily integrate Google Tag Manager with tracking for scroll events, forms, and WooCommerce, all manageable from the WordPress dashboard.
Tracking for Divi Developer Profile
1 plugin · 100 total installs
How We Detect Tracking for Divi
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tracking-for-divi/js/dist/assets/index.js/wp-content/plugins/tracking-for-divi/js/dist/assets/index.css/wp-content/plugins/tracking-for-divi/js/dist/js/client/main.tstracking-for-divi/style.css?ver=tracking-for-divi/script.js?ver=HTML / DOM Fingerprints
tracking-for-divi-settings-pagedata-tracking-for-divi-send-datalayerdata-tracking-for-divi-datalayer-variabledata-tracking-for-divi-datalayer-eventdata-tracking-for-divi-include-all-datadata-tracking-for-divi-send-gtagdata-tracking-for-divi-gtag-event+3 moreTRACKING_FOR_DIVI_OPTIONS